Infection Channel: Downloaded from the Internet, Dropped by other malware, Propagates via instant messaging applications
This worm arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It does not have any backdoor routine.
It does not drop any other file.
It does not have any downloading capability.
It does not have any information-stealing capability.
File size: 17,408 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 25 Dec 2012
Payload: Sends messages
Arrival Details
This worm arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Backdoor Routine
This worm does not have any backdoor routine.
Dropping Routine
This worm does not drop any other file.
Download Routine
This worm does not have any downloading capability.
Information Theft
This worm does not have any information-stealing capability.
NOTES:
This worm propagates via Skype. When an infected user uses Skype to chat with someone, this worm types and sends out the following message:
- LOL http://www.{BLOCKED}x.uk.com/images.php?id=IMG0540250.JPG
Here is a sample screenshot:
The message contains a link that may possibly lead to malware. However, the link is now inaccessible.
It does not have rootkit capabilities.
It does not exploit any vulnerability.
Connect with us on
| | | |